Home/Threat Actor/TAG-110
Threat Actor

TAG-110

tag_110 · russia · active since 2021-01

TAG-110 (Recorded Future Insikt Group canonical designation, November 21, 2024 first-disclosure.

tracked under adjacent designation UAC-0063 by CERT-UA) is a Russia-aligned cyber espionage cluster conducting cyber espionage operations against Central Asian governments (~30 documented victims in Kazakhstan, additional in Tajikistan, Kyrgyzstan, Uzbekistan, Turkmenistan) and Ukrainian governmental organizations, approximately 62 total documented victims; Central Asian government targeting consistent with Russian state intelligence priorities of monitoring Central Asian political alignment, China vs. West economic relations, and regional security alliances.

signature operational tradecraft is spearphishing with malicious Word documents, custom backdoor deployment (HATVIBE, CHERRYSPY Python-based backdoor), and DLL side-loading delivery chains; operationally distinct from Western-targeting major Russian- aligned clusters (APT28, APT29, Sandworm, Turla) and from Ukraine-focused Gamaredon, all curated separately in this corpus.

operational relationship to CERT-UA UAC-0063 designation remains analytical open question (operationally- identical vs operationally-overlapping vs operationally- distinct with tooling overlap).

russia confidence: high 9 aliases

Profile

TAG-110 (Recorded Future Insikt Group canonical designation, November 21, 2024 first-disclosure.

tracked under adjacent / overlapping designation UAC-0063 by CERT-UA) is a Russia- aligned cyber espionage cluster conducting cyber espionage operations against Central Asian governments, Ukrainian governmental organizations, and adjacent targets. The cluster's targeting profile is operationally distinctive in the Russian-aligned cyber-operations ecosystem, approximately 62 documented victim organizations span Kazakhstan (~30 victims, heaviest concentration), Tajikistan, Kyrgyzstan, Uzbekistan, Turkmenistan, and selectively additional geographies. The Central Asian government targeting concentration is operationally consistent with Russian state intelligence priorities of monitoring Central Asian state political alignment (particularly regarding economic relations with China versus the West, energy export relationships, and regional security alliances), but operationally distinct from the Western-targeting focus of major Russian-aligned clusters (APT28, APT29, Sandworm) and the Ukraine-focused targeting of Gamaredon. The cluster represents one of the most operationally-significant documented Central Asian- targeting clusters in the Russian-aligned cyber-operations ecosystem. Operational tradecraft includes spearphishing operations with malicious Microsoft Word documents containing macros for initial access, custom backdoor deployment (HATVIBE, signature custom backdoor.

CHERRYSPY, custom Python-based backdoor), DLL side-loading delivery chains, and operational coordination consistent with broader Russian- aligned cyber-operations tradecraft. The HATVIBE and CHERRYSPY custom tooling operationally distinguishes TAG-110 from clusters relying primarily on commodity tooling. TAG-110's operational relationship to the CERT-UA-tracked UAC-0063 designation remains an open analytical question, whether UAC-0063 and TAG-110 represent operationally- identical clusters with different vendor designations, operationally-overlapping clusters with shared operator- network origin, or operationally-distinct clusters with tooling overlap. The dual-designation tracking pattern is operationally similar to other dual-tracking patterns observed across the broader threat-intelligence vendor ecosystem. TAG-110 is operationally distinct from all other Russian- aligned clusters curated separately in this corpus and fills the Central-Asian-government-targeting cell in the curated Russian-cluster coverage.

Aliases

9
tag_110tag-110tag 110threat activity group 110uac_0063uac-0063russia-aligned-tag-110-clustercentral-asia-targeting-russia-aligned-clustertag110

Notable Campaigns

3
2024Recorded Future Insikt Group Canonical Public Disclosure, TAG-110 (November 2024)
2023-2024CERT-UA UAC-0063 Adjacent / Overlapping Tracking
2021-2024Central Asian Government Targeting Operational Signature

Attribution & Reporting

Attributed by
Recorded Future Insikt GroupCERT-UA (Computer Emergency Response Team of Ukraine, UAC-0063 tracking)Mandiant (Google Threat Intelligence)Microsoft Threat IntelligenceSentinelOneCrowdStrikeKazakhstan KZ-CERT
Key reporting
reportRecorded Future Insikt Group: TAG-110 Targets Eurasia and Central Asia (November 21, 2024), canonical first-disclosure
reportCERT-UA: UAC-0063 Tracking (Adjacent / Overlapping Cluster)
reportMandiant / Google Threat Intelligence: TAG-110 Russia-Aligned Central Asia Analysis
reportMicrosoft Threat Intelligence: Russia-Aligned Central Asian Government Targeting
reportMalpedia Actor Profile: TAG-110

Operational

State sponsor

Russia-aligned cyber espionage cluster assessed by Recorded Future Insikt Group (canonical TAG-110 designation, November 2024 disclosure) and the Computer Emergency Response Team of Ukraine (CERT-UA, UAC-0063 designation, adjacent tracking) as operating as a Russia-aligned advanced persistent threat actor conducting cyber espionage operations against Central Asian governments, Ukrainian governmental organizations, and adjacent targets within the broader Russian state intelligence-collection priority space. Recorded Future's analysis of TAG-110 documented operational tradecraft, infrastructure patterns, and tooling overlaps consistent with adjacent Russian state-aligned cluster tradecraft, particularly operational overlaps with the broader UAC-0063 / Russia-aligned operational cluster space tracked by CERT-UA. The cluster's targeting profile is operationally distinctive, Central Asian governmental organizations (Kazakhstan, Tajikistan, Kyrgyzstan, Uzbekistan, Turkmenistan) represent the cluster's signature targeting concentration, consistent with Russian state intelligence priorities of monitoring Central Asian state political alignment, economic relations with China and the West, and adjacent strategic intelligence-value information.

Ukrainian governmental targeting represents secondary operational priority. The cluster has not been formally attributed by any government cybersecurity authority to a specific Russian government agency, military intelligence service (GRU), or civilian intelligence service (SVR / FSB). The cluster is operationally distinct from major Russian- aligned clusters curated separately in this corpus including APT28 / Fancy Bear (apt28_fancybear.yaml, GRU 26165), APT29 / Cozy Bear (apt29_cozybear.yaml, SVR), Sandworm (sandworm.yaml, GRU 74455), Turla (turla.yaml, FSB Center 16), and Gamaredon (gamaredon.yaml, FSB-affiliated Ukraine-focused), though all operate within the broader Russian-aligned cyber-operations ecosystem.

Motivations
cyber_espionage, central_asian_government_intelligence_collection, ukrainian_government_intelligence_collection, russian_state_intelligence_priorities, geopolitical_intelligence_collection
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)60/60 · 100%
Analytics (MITRE CAR)33/60 · 55%
Runtime / container (Falco)10/60 · 16%
File / malware (YARA)1/60 · 1%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MALICIOUS OFFICE DOCUMENTS

CVEs Exploited

2
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin